diff --git a/mnemo_cards_backend/isar/db.isar b/mnemo_cards_backend/isar/db.isar index 8134a5d..4411246 100644 Binary files a/mnemo_cards_backend/isar/db.isar and b/mnemo_cards_backend/isar/db.isar differ diff --git a/tools/deploy/backend-build_app.sh b/tools/deploy/backend-build_app.sh index 70674fc..a550604 100644 --- a/tools/deploy/backend-build_app.sh +++ b/tools/deploy/backend-build_app.sh @@ -86,6 +86,7 @@ else -d api.mnemo-cards.online \ -d code.mnemo-cards.online \ -d vscode.mnemo-cards.online \ + -d admin.mnemo-cards.online \ --cert-name mnemo-cards.online \ --non-interactive --agree-tos --email admin@mnemo-cards.online; then echo "✅ Let's Encrypt multi-domain сертификат успешно создан!" diff --git a/tools/ssl/renew_admin_ssl.sh b/tools/ssl/renew_admin_ssl.sh new file mode 100755 index 0000000..51504b2 --- /dev/null +++ b/tools/ssl/renew_admin_ssl.sh @@ -0,0 +1,133 @@ +#!/bin/bash + +# SSL Certificate Renewal Script for admin.mnemo-cards.online +# This script obtains Let's Encrypt SSL certificate for admin panel +# Usage: ./renew_admin_ssl.sh + +set -e + +DOMAIN="admin.mnemo-cards.online" +EMAIL="admin@mnemo-cards.online" + +echo "🔐 Starting SSL certificate renewal for $DOMAIN..." + +# Colors for output +RED='\033[0;31m' +GREEN='\033[0;32m' +YELLOW='\033[1;33m' +BLUE='\033[0;34m' +NC='\033[0m' # No Color + +print_status() { + echo -e "${GREEN}[INFO]${NC} $1" +} + +print_warning() { + echo -e "${YELLOW}[WARNING]${NC} $1" +} + +print_error() { + echo -e "${RED}[ERROR]${NC} $1" +} + +print_success() { + echo -e "${GREEN}[SUCCESS]${NC} $1" +} + +# Check if certbot is installed +if ! command -v certbot &> /dev/null; then + print_status "Installing certbot..." + apt update + apt install -y certbot +fi + +# Check current nginx status +NGINX_RUNNING=false +if systemctl is-active --quiet nginx; then + NGINX_RUNNING=true + print_status "nginx is currently running" +else + print_status "nginx is currently stopped" +fi + +# Stop nginx for standalone mode +if [ "$NGINX_RUNNING" = true ]; then + print_status "Stopping nginx for certificate renewal..." + systemctl stop nginx + sleep 2 +fi + +# Obtain certificate +print_status "Obtaining SSL certificate for $DOMAIN..." +if certbot certonly --standalone \ + -d "$DOMAIN" \ + --email "$EMAIL" \ + --agree-tos \ + --non-interactive; then + + print_success "SSL certificate obtained successfully!" + + # Verify certificate files exist + if [ -f "/etc/letsencrypt/live/$DOMAIN/fullchain.pem" ] && [ -f "/etc/letsencrypt/live/$DOMAIN/privkey.pem" ]; then + print_success "Certificate files verified" + + # Set proper permissions + chmod 600 "/etc/letsencrypt/live/$DOMAIN/privkey.pem" + chmod 644 "/etc/letsencrypt/live/$DOMAIN/fullchain.pem" + + print_success "Certificate permissions set" + else + print_error "Certificate files not found after renewal!" + exit 1 + fi +else + print_error "Failed to obtain SSL certificate!" + exit 1 +fi + +# Start nginx back +if [ "$NGINX_RUNNING" = true ]; then + print_status "Starting nginx..." + systemctl start nginx + sleep 2 + + if systemctl is-active --quiet nginx; then + print_success "nginx started successfully" + else + print_error "Failed to start nginx!" + exit 1 + fi +fi + +# Test certificate validity +print_status "Testing certificate validity..." +if openssl x509 -in "/etc/letsencrypt/live/$DOMAIN/cert.pem" -text -noout | grep -q "Subject:.*$DOMAIN"; then + print_success "Certificate is valid for $DOMAIN" +else + print_error "Certificate validation failed!" + exit 1 +fi + +# Test HTTPS connection +print_status "Testing HTTPS connection..." +if curl -I --max-time 10 "https://$DOMAIN/" 2>/dev/null | grep -q "200\|301\|302"; then + print_success "HTTPS connection to $DOMAIN is working" +else + print_warning "HTTPS connection test failed - this may be normal if nginx config needs reloading" +fi + +# Setup auto-renewal cron job +print_status "Setting up automatic renewal..." +CRON_JOB="0 12 * * * /usr/bin/certbot renew --quiet --post-hook \"systemctl reload nginx\" --cert-name $DOMAIN" + +# Check if cron job already exists +if ! crontab -l 2>/dev/null | grep -q "certbot.*$DOMAIN"; then + (crontab -l 2>/dev/null; echo "$CRON_JOB") | crontab - + print_success "Auto-renewal cron job added" +else + print_info "Auto-renewal cron job already exists" +fi + +print_success "SSL certificate renewal completed successfully! 🎉" +print_info "Certificate will auto-renew before expiration" +print_info "Admin panel is now available at: https://$DOMAIN"